Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FortiNAC (FNC-CA / FNC-M)

FortiNAC Network Access Control

See every device on the network, and control what it can reach

Compare all 4 models

Figures are Fortinet’s own, sortable, cited on every product page
FortiNAC Network Access Control model comparison
ModelActions
FortiNAC CA-500FFNC-CA-500FMid-range control and application serverSmall environmentsManages up to 5,000 ports in the networkDetails
FortiNAC CA-600FFNC-CA-600FHigh performance control and application serverMedium environmentsManages up to 15,000 ports in the networkDetails
FortiNAC CA-700CFNC-CA-700CUltra high performance control and application serverLarge environments with few persistent agentsManages up to 25,000 ports in the networkDetails
FortiNAC M-550FFNC-M-550FCentralized management applianceMulti-site deployments with multiple appliancesManages up to 50 CA serversDetails

How to read these numbers

FortiNAC answers a question most organisations cannot: what is actually connected. It discovers and profiles every device, including the unmanaged and unmanageable ones, cameras, badge readers, infusion pumps, PLCs, and then enforces what each is allowed to reach.

More on choosing within this range

It works agentlessly across multi-vendor infrastructure, so it covers the switches and wireless you already own rather than requiring a forklift. Enforcement is by dynamic VLAN assignment and ACLs pushed to the access layer.

Sizing is by ports in the network, and Fortinet is explicit that this means total switch ports plus maximum concurrent wireless connections, not the number of devices you think you have. The FNC-CA-500F covers up to 5,000 ports, the 600F up to 15,000, the 700C up to 25,000, and the FNC-M-550F is a management appliance for up to 50 control servers.

Before you order

How many ports, really?

Count every access-layer switch port plus your peak concurrent wireless client count. Under-sizing here is the most common FortiNAC purchasing error and it is not cheap to correct.

How many sites?

Multi-site deployments with several control servers need the FNC-M-550F management appliance on top of the control appliances. Single site does not.

Do you need persistent agents?

The 700C is specified for large environments with few persistent agents. If you plan heavy agent-based posture assessment, that changes the sizing, tell us the split.

What are you actually trying to fix?

If the goal is IoT and OT visibility, FortiNAC is the right tool. If it is user authentication for corporate laptops, 802.1X through FortiAuthenticator may be a much smaller project.

All FortiNAC Network Access Control